
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-3903 is a memory corruption vulnerability discovered in Apple's macOS operating systems (Catalina 10.15.3, Mojave 10.14.6, and High Sierra 10.13.6). The vulnerability was discovered by Proteas of Qihoo 360 Nirvan Team and was addressed by Apple in the macOS Catalina 10.15.4 and Security Update 2020-002 updates released on March 24, 2020 (Apple Security).
The vulnerability exists in the Apple HSSPI Support component and allows an application to execute arbitrary code with system privileges. The issue was specifically identified as a memory corruption vulnerability that was remediated through improved memory handling implementations (Apple Security).
The vulnerability's primary impact is that it allows malicious applications to execute arbitrary code with system privileges, which effectively provides complete control over the affected system. This level of access could potentially allow an attacker to perform any action on the compromised system (Apple Security).
Apple addressed this vulnerability in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, and Security Update 2020-002 High Sierra, released on March 24, 2020. Users should update to these versions or later to protect against this vulnerability (Apple Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."